1

Cybersecurity Deception Engineer Jobs (NOW HIRING)

Forward Deployed Engineer

New York, NY ยท On-site

$120K - $220K/yr

We're not just another cybersecurity company. We're defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and ...

We're not just another cybersecurity company. We're defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and ...

Software Engineer, Detection

New York, NY ยท On-site

$150K - $350K/yr

We're not just another cybersecurity company. We're defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and ...

Software Engineer, Simulation

New York, NY ยท On-site

$135K - $350K/yr

We're not just another cybersecurity company. We're defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and ...

We're not just another cybersecurity company. We're defining the future of social engineering defense, where trust is protected, and deception becomes unprofitable. Backed by top-tier investors and ...

Showing results 21-40

Cybersecurity Deception Engineer information

See salary details

$40.5K

$122.9K

$180K

How much do cybersecurity deception engineer jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cybersecurity deception engineer in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What is a cybersecurity deception engineer?

A Cybersecurity Deception Engineer is a professional who designs, implements, and manages deception technologies within an organization's cybersecurity infrastructure. Their main role is to create decoys, traps, and fake assets that mimic real systems to lure, detect, and analyze cyber attackers without exposing actual sensitive data. This proactive approach helps organizations identify threats early, understand attacker behavior, and strengthen their overall security posture. Deception engineers often collaborate with incident response teams and use specialized tools to deploy and monitor these deceptive environments.

What are the key skills and qualifications needed to thrive as a cybersecurity deception engineer?

To thrive as a Cybersecurity Deception Engineer, you need a solid background in cybersecurity principles, network protocols, threat analysis, and typically a degree in computer science or a related field. Familiarity with deception platforms (like Attivo or Illusive), SIEM tools, scripting languages (such as Python or PowerShell), and certifications like CISSP or CEH are highly valued. Strong problem-solving abilities, creativity, and effective communication skills help in designing innovative deception strategies and collaborating with cross-functional teams. These skills and qualities are crucial for proactively detecting threats, misleading adversaries, and enhancing overall organizational security.

What are some common challenges faced by cybersecurity deception engineers during the deployment of deception technologies?

One common challenge for Cybersecurity Deception Engineers is ensuring that decoy assets and traps are realistic enough to attract attackers without disrupting legitimate network operations. Balancing visibility and stealth is crucial, as overly obvious decoys may be ignored by threat actors, while poorly integrated ones could alert adversaries or create unnecessary alerts for security teams. Additionally, coordinating with IT and security teams to keep decoys updated and relevant as the organization's infrastructure evolves can be complex. Effective collaboration and continuous tuning are essential to maximize the value of deception technologies.

What are popular job titles related to Cybersecurity Deception Engineer jobs?

For Cybersecurity Deception Engineer jobs, the most frequently searched job titles are:

Infographic showing various Cybersecurity Deception Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Cybersecurity/Info Security Engineer (Remote- 130K)

Manhattan, NY โ€ข On-site

Merit Personnel & Consulting
1 - 10 employees

Other

Re-posted 6 days ago


Key responsibilities

  • Build and administer core network and systems security controls, including firewalls, intrusion detection and prevention, anti-malware, application whitelisting, host intrusion prevention, endpoint detection and response (EDR), privileged access management (PAM), vulnerability scanners, security monitoring (SIEM), and enterprise authentication and authorization.

  • Plan and execute Information Security projects, represent the security team on projects owned by other IT teams, and help define and document the firm's Information Security Architecture and Roadmap.

  • Implement and operate technical security solutions, participate in incident response efforts, and assist with threat and vulnerability management activities.


Job description

Cybersecurity/Info Security Engineer (Remote- 130K)

Title: โ€œCybersecurity/Information Security Engineerโ€

Location: Remote

GENERAL SUMMARY:

The Information Security Engineer is a key member of the technology team that evaluates the firmโ€™s technology and information systems to develop security strategies and solutions to protect the Firm from internal and external threats.

This position supports the firmโ€™s overall information security program by evaluating, testing, documenting, and implementing products and solutions, continuous management and monitoring of software, analyzing and remediation of security incidents and alerts. The Information Security Engineer is accountable for planning and executing security projects to improve the Firmโ€™s overall security posture; for creating and maintaining of security-related documentation and for other various security-related tasks. Information Security Engineers are responsible for the protection of all Information Assets, including physical and digital data, technology infrastructure, cloud and on-premise applications, user endpoints, identities and other Technology Resources.

Information Security Engineers must continually adapt to understand and stay a step ahead of the latest cyber threats. The ideal candidate is passionate about security, is intellectually curious, and thrives on learning, teaching and mentoring alike. The firmโ€™s security team values and is committed to fostering a cooperative leadership and learning environment from every chair, regardless of title.

ESSENTIAL JOB FUNCTIONS :

  • Build and administer core network and systems security controls, including: firewalls, intrusion detection and prevention, anti-malware, application whitelisting, host intrusion prevention, endpoint detection and response (EDR), privileged access management (PAM), privilege elevation, vulnerability scanners, content monitoring / filtering, security monitoring (SIEM), enterprise authentication and authorization.
  • Plan and execute Information Security projects. Represent the security team on projects owned by other IT teams.
  • Perform security and privacy reviews of IT services and changes (e.g., new technologies being added to the environment or that are undergoing significant changes). Monitor change management database activity to stay abreast of developments in the IT environment.
  • Help define and document the firmโ€™s Information Security Architecture and Roadmap.
  • Based on the Firmโ€™s IT Risk Assessment, plan for the lifecycle, implementation and integration of future security technologies with other security and non-security technologies. Recommend and drive technology and process improvements for Information Security Programs.
  • Collaborate actively with senior technologists on other IT teams to design solutions that satisfy the priorities of each individual IT team involved, while also providing the best possible user experience and appropriate security assurance.
  • Interface and cooperate with internal and external audit and exam teams as required.
  • Establish architectures and baseline configurations for various security technologies, including: anti-malware, endpoint detection and response (EDR), security monitoring, systems security, network security, identity and access management, public-key infrastructure (PKI), deception technologies, DLP and web/e-mail content filtering.
  • Design and maintain strategies for Information Security documentation, including runbooks, procedures, processes and hardware and software inventory detail.
  • Implement and operate technical security solutions across a wide range of technologies, and serve as a third-tier support resource and SME for these technologies as required.
  • Participate in technical and non-technical projects requiring information security oversight to ensure policies, procedures and standards are met.
  • Serve as a member of the Computer Security Incident Response Team (CSIRT), assisting with incident response (IR) with the IR and security operations center (SOC) efforts.
  • Recommend new security solutions as well as effective improvements to existing security controls that do not negatively impact business innovation.
  • Assist with threat and vulnerability management activities, including: triage of new vulnerabilities, root cause analysis, threat modeling and mitigation planning.
  • Coordinate closely with Information Security Governance, Security Operations and various teams throughout the firm to align information protection strategies with technologies and functions throughout the firm.
  • In coordination with Information Security Governance, publish and maintain appropriate Information Security policies and standards to help guide selection and implementation of various technologies, throughout the IT organization.
  • Assist with Information Security program management, including defining and documenting corporate security policies and procedures, security metrics, and coordinating the security awareness program.
  • Automate workflows for security processes and procedures. Identify and drive improvements to Information Security programs.
  • Provide technical guidance, training and direction to less experienced staff. Take a proactive approach to mentoring other staff members.
  • Participate in DR planning and testing activities.
  • May require on-call as assigned.
  • Other duties as assigned.

Additional Job Description

QUALIFICATIONS / KSAs:

  • Bachelorโ€™s degree in Computer Science, Information Systems, Computer Engineering or related discipline, or equivalent experience and technical background.
  • At least 6 years of relevant experience.
  • Strong technical knowledge and understanding of security concepts, for example: network/perimeter security, security event monitoring, vulnerability assessment, intrusion detection and response, encryption technologies, enterprise authentication (e.g., SAML/SSO, Active Directory, etc.), EDR, PAM and content monitoring/filtering.
  • Strong technical knowledge and understanding of key technology platforms.
  • Working knowledge of network and security protocols including TCP/IP, SMTP, FTP, SSH, TLS, SSL, HTTP, IPSec and other VPN protocols.
  • Strong written and verbal communications skills. Ability to speak and explain complex security issues to audiences without similar backgrounds.
  • Ability to effectively communicate business risk as it relates to information security.
  • Excellent time management and organizational skills to effectively meet multiple objectives.
  • Results oriented, self-motivated and capable of performing several tasks simultaneously.
  • Strong analytical, process and troubleshooting skills.
  • The desire, commitment and ability to be a team player.
#J-18808-Ljbffr